<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Passing traffic through 6200P via bonded and bridged interfaces in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Passing-traffic-through-6200P-via-bonded-and-bridged-interfaces/m-p/147219#M23486</link>
    <description>&lt;P&gt;We are attempting to deploy a 6200 between Cisco switch stacks via bridged interfaces.&amp;nbsp; Topology is such that Stack 1 connects to Stack 2 and Stack 3 via separate 2 port Etherchannels).&amp;nbsp; We have configured the Checkpoint with 2 Bridge interfaces (comprised of 2 bonds each).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-04-27_11-50-16.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16210i6694150EC8929EF0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-04-27_11-50-16.jpg" alt="2022-04-27_11-50-16.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In limited testing, this deployment appears to be working okay.&amp;nbsp; However, when attempting to move to production, certain traffic doesn't pass, even with an Any Any allow rule.&amp;nbsp; &amp;nbsp;There are a lot of "Data received before SYN was acknowledged" entries in the logs.&amp;nbsp; Any thoughts as to if this is somehow config related to the bridge or bond setups?&amp;nbsp; There doesn't seem to be much in the way of options when configuring them.&lt;/P&gt;&lt;P&gt;Thanks for any assistance,&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2022 16:03:09 GMT</pubDate>
    <dc:creator>jacowser</dc:creator>
    <dc:date>2022-04-27T16:03:09Z</dc:date>
    <item>
      <title>Passing traffic through 6200P via bonded and bridged interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Passing-traffic-through-6200P-via-bonded-and-bridged-interfaces/m-p/147219#M23486</link>
      <description>&lt;P&gt;We are attempting to deploy a 6200 between Cisco switch stacks via bridged interfaces.&amp;nbsp; Topology is such that Stack 1 connects to Stack 2 and Stack 3 via separate 2 port Etherchannels).&amp;nbsp; We have configured the Checkpoint with 2 Bridge interfaces (comprised of 2 bonds each).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-04-27_11-50-16.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16210i6694150EC8929EF0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-04-27_11-50-16.jpg" alt="2022-04-27_11-50-16.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In limited testing, this deployment appears to be working okay.&amp;nbsp; However, when attempting to move to production, certain traffic doesn't pass, even with an Any Any allow rule.&amp;nbsp; &amp;nbsp;There are a lot of "Data received before SYN was acknowledged" entries in the logs.&amp;nbsp; Any thoughts as to if this is somehow config related to the bridge or bond setups?&amp;nbsp; There doesn't seem to be much in the way of options when configuring them.&lt;/P&gt;&lt;P&gt;Thanks for any assistance,&lt;/P&gt;&lt;P&gt;Jerry&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 16:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Passing-traffic-through-6200P-via-bonded-and-bridged-interfaces/m-p/147219#M23486</guid>
      <dc:creator>jacowser</dc:creator>
      <dc:date>2022-04-27T16:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Passing traffic through 6200P via bonded and bridged interfaces</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Passing-traffic-through-6200P-via-bonded-and-bridged-interfaces/m-p/147297#M23507</link>
      <description>&lt;P&gt;Those messages often related to a specific protection: "&lt;SPAN&gt;TCP SYN Modified Retransmission"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It's necessary to understand the specific traffic flow that is triggering this to determine if their is a networking problem or other cause that can be otherwise handled.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Refer also:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk63160" target="_self"&gt;sk63160: Aggregated TCP logs (Potential Network Configuration Problem)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 07:31:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Passing-traffic-through-6200P-via-bonded-and-bridged-interfaces/m-p/147297#M23507</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-28T07:31:32Z</dc:date>
    </item>
  </channel>
</rss>

